Trojan

About “Trojan:Win32/Obfuscator.RB!MTB” infection

Malware Removal

The Trojan:Win32/Obfuscator.RB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Obfuscator.RB!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/Obfuscator.RB!MTB?


File Info:

name: 01E222957718A13FAD9B.mlw
path: /opt/CAPEv2/storage/binaries/0c146039c97ee376e46662f545294c97c4a7ba4e3e27d0bd2a6d63eb324bc505
crc32: 6CF0EA1F
md5: 01e222957718a13fad9bf2d1849595cc
sha1: 565cbec3983515f0ce975ddcb1506395cbe2d0d3
sha256: 0c146039c97ee376e46662f545294c97c4a7ba4e3e27d0bd2a6d63eb324bc505
sha512: a60706fcb94b15e10410eb64fcb64c3644b29f24ad4331f7ca21dff63411e50743f16cc20ccf37363361a9bb3750f288aac40ceb4000e6465f726905ea5dca9c
ssdeep: 3072:FG5rc1rmz4ak+8JfTctQOvh4ss7e7OzgYEUb/6r8TVl4p1iCtkJU:F20ak53Ovmssp3EUjQe4p1iC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10344AE4276D1D9B1EA67063189698AA01E7EFD714F357A8733442B0FA9703E1A633F13
sha3_384: cd44b85ba15d30be098f3d9cb259ef49a3977c3a540e851462d36edd87db11d0530b7fd23672bfde4115cde87b058e66
ep_bytes: e89c470000e97ffeffffcccccccccc57
timestamp: 2019-04-14 07:28:14

Version Info:

0: [No Data]

Trojan:Win32/Obfuscator.RB!MTB also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Zenpak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ser.Mikey.2088
McAfeePacked-GBN!01E222957718
CylanceUnsafe
VIPREGen:Variant.Ser.Mikey.2088
SangforTrojan.Win32.Save.a
K7AntiVirusRansomware ( 005686901 )
BitDefenderGen:Variant.Ser.Mikey.2088
K7GWRansomware ( 005686901 )
Cybereasonmalicious.57718a
CyrenW32/Kryptik.BZV.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HDXH
CynetMalicious (score: 100)
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Generickdz-8528045-0
KasperskyHEUR:Trojan.Win32.Zenpak.pef
AlibabaMalware:Win32/km_24ad5.None
NANO-AntivirusTrojan.Win32.Kryptik.hlsxra
RisingTrojan.Kryptik!1.C783 (CLASSIC)
Ad-AwareGen:Variant.Ser.Mikey.2088
EmsisoftGen:Variant.Ser.Mikey.2088 (B)
DrWebTrojan.MulDrop4.25343
McAfee-GW-EditionBehavesLike.Win32.Emotet.dh
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.01e222957718a13f
SophosMal/Generic-S
AviraHEUR/AGEN.1228643
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.61DD
MicrosoftTrojan:Win32/Obfuscator.RB!MTB
SUPERAntiSpywareTrojan.Agent/Gen-Chapak
ZoneAlarmHEUR:Trojan.Win32.Zenpak.pef
GDataGen:Variant.Ser.Mikey.2088
GoogleDetected
AhnLab-V3Trojan/Win32.MalPe.R339868
ALYacGen:Variant.Ser.Mikey.2088
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Glupteba
PandaTrj/GdSda.A
TencentWin32.Trojan.Zenpak.Bdhl
IkarusTrojan.Win32.Danabot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HDZQ!tr
BitDefenderThetaGen:NN.ZexaF.34698.qqW@aK9Stmme
AVGWin32:CoinminerX-gen [Trj]
AvastWin32:CoinminerX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Obfuscator.RB!MTB?

Trojan:Win32/Obfuscator.RB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment